← Radar

Incident case file

Sign in to watch

Ekubo EVM v2 Router — Approval-Based Token Drain Exploit

Incident date May 5, 2026

0 views

UnknownEthereumApproval-based exploit / Router callbackCluster: EKUBO-ETH-2026-05

Estimated loss

$1.4M

Victims identified

5
Victim group joining is coming soon.

Investigation

80%

Facts and investigation

Attacker: Unidentified EOA (funded via Railgun pre-attack)

Funds moved to: WBTC → WETH → DAI → Tornado Cash (laundering chain)
Primary victim wallet (17 WBTC drained): 0x765DEC... (partial, per Bitget/SlowMist analysis). Attacker funded via Railgun prior to the exploit. Stolen WBTC was converted to WETH then DAI before being laundered through Tornado Cash. Approximately 85 rapid transactions of 0.2 WBTC each were executed against wallets holding prior approvals to the Ekubo EVM v2 router.

Timeline: On May 5, 2026 at approximately 22:18 UTC, an attacker exploited an IPayer.pay callback vulnerability in Ekubo Protocol's EVM v2 swap router, draining 17 WBTC (~$1.4M) from wallets that had granted prior token approvals to the router. The exploit was carried out through ~85 rapid transactions of 0.2 WBTC each. The attacker's wallet had been pre-funded via Railgun, indicating premeditation. Stolen WBTC was converted to WETH and DAI, then sent through Tornado Cash for laundering. Ekubo announced the breach via its official X account and confirmed that Starknet contracts were unaffected (the exploit was limited to the EVM deployment). Critically, the Ekubo EVM contracts are immutable, meaning the team must redeploy rather than patch. Ekubo launched a refund portal and Revoke.cash issued a dedicated approval-revocation tool. The investigation is effectively closed pending any potential attacker identification.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)